CVE-2024-9365
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 352
Summary
CVE-2024-9365 is a Cross-Site Request Forgery (CSRF) vulnerability affecting polyaxon/polyaxon version 2.4.0. Attackers can exploit this flaw to execute unauthorized actions in a victim's browser, including creating projects, model versions, artifact versions, and altering settings. This vulnerability poses a significant risk of data loss and service disruption. Users are strongly encouraged to update their polyaxon installation as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.